A USB port.
Your data stolen.
Two attack vectors simulated: a compromised public charging kiosk and a malicious USB cable. With silent data exfiltration and payload injection.
Public USB kiosk
CDG Airport — Gate H
Inside the casing:
⚠ Outer appearance 100% identical to a normal kiosk
An airport charging kiosk
It looks like all the others. On the surface, nothing distinguishes it from a normal kiosk.
A tiny computer hidden inside the casing
Compromised kiosks contain a Raspberry Pi Zero or similar device (< €15) connected to the USB port. The outer casing is intact — no visible modification. The device silently waits for a phone to connect.
Key figures
< 0 min
To exfiltrate a smartphone
full data via a compromised kiosk
0 trace
On the victim's phone
no alert or notification during the attack
~$0
Price of a USB data blocker
fully neutralizes juice jacking
Technical demo
Try it yourself
Two attack vectors simulated: a compromised USB kiosk exfiltrating mobile data, and a malicious USB cable with HID injection and a reverse shell.
Interactive demonstration
Juice jacking simulator
Attack flow
Your phone
USB-C
Charging kiosk
Harmless?
Hidden chip
BadUSB
C2 server
Listening
Note: the kiosk correctly shows the charge on the phone's screen. The attack is completely silent and invisible to the user.
Compromised charging kiosk
A public USB kiosk integrates a hidden microcontroller that activates the data interface on connection. The phone's OS treats it as a trusted accessory.
Malicious USB cable
A normal-looking cable (~$30–180) embeds a BadUSB chip. It identifies itself as an HID keyboard and injects PowerShell commands within seconds.
USB blocker (protection)
A ~$5 adapter physically cuts the D+ and D− pins. Only electrical power passes through. Compatible with all USB-A and USB-C kiosks.
Real-world example
FBI Alert · April 2023
Officially documented.
In April 2023, the FBI's Denver field office issued an official warning recommending against using public USB charging kiosks in airports, hotels, and shopping centers. The FCC had issued a similar alert as early as 2021, confirming real data-exfiltration incidents via compromised kiosks.
What authorities recommend
→Use your own wall-outlet adapter
→Carry a personal power bank when traveling for work
→Use a USB blocker if a public kiosk is unavoidable
Most targeted sectors
Airports & train stations
High traffic, long waits
Hotels & conference rooms
High-value professional targets
Shopping malls
Kiosks often unsupervised
Transportation (trains, planes)
Onboard USB ports hard to audit